Available — open to remote roles worldwide

MD Sadat Tamzit

// Offensive Security Researcher · Penetration Tester · Application & API Security Engineer

Three-plus years of hands-on web and API penetration testing: 2000+ vulnerabilities reported across 150+ organisations, a publicly disclosed U.S. Department of Defense SQL injection, and a top-50 global rank on the HackerOne VDP leaderboard.

sadat@recon: ~/career_status
Scroll
2000+ Vulnerabilities reported (lifetime)
150+ Organisations
40+ Client engagements
85–90% Report acceptance rate
#42 / #2 HackerOne VDP — global / Bangladesh
About

Executive Summary

I'm an offensive security researcher and penetration tester based in Dhaka, Bangladesh, currently working as a Security Engineer at Disclosify, where I run manual web application and API penetration tests for client organisations against OWASP and PTES methodology. Alongside client work, I've spent the last three-plus years hunting vulnerabilities independently on HackerOne and Bugcrowd — from business-logic flaws to blind SQL injection — and mentoring newer researchers through Daffodil International University's Cyber Security Club.

Across both tracks I've filed 2000+ vulnerability reports across 150+ organisations, sustaining an 85–90% acceptance rate on my client work at Disclosify. My published findings include a publicly disclosed unauthenticated SQL injection on a U.S. Department of Defense system and a CVSS 9.8 business-logic flaw. I hold certifications spanning web, API and network security — eWPTX v3, CASA, ASCP, CNSP and CAP — and I'm actively looking for a fully remote role, or one offering visa sponsorship and relocation, with a security-focused team in Europe or the US.

Web App Pentesting API Security (REST & GraphQL) Business Logic Flaws SQL Injection OWASP Top 10 Coordinated Disclosure
At A Glance
LocationDhaka, Bangladesh
AvailabilityRemote worldwide · visa sponsorship OK
Download Full CV
Services

What I Can Do For You

Engagement types available for client assessments and freelance work, alongside full-time roles.

Web Application Penetration Testing

Comprehensive security assessment of web applications following OWASP methodology, specialising in XSS, SQL injection, SSRF, RCE, LFI and CSRF.

XSSSQLiSSRFRCELFICSRF

iOS Application Testing

Security testing for iOS mobile applications, including binary analysis, API testing, and a review of on-device data storage.

Binary AnalysisAPI TestingData Storage

Network Penetration Testing

External and internal network security assessments to identify misconfigurations, weak protocols and exploitable services.

ExternalInternalMisconfigurations

Red Team Operations

Full red team engagements covering exploitation, privilege escalation, pivoting, persistence and defense-evasion techniques.

ExploitationPrivilege EscalationPersistenceEvasion
Disclosures

Notable Disclosures

A selection of vulnerabilities I've responsibly disclosed — each verified end-to-end with a working proof of concept before submission.

FINDING · U.S. DEPARTMENT OF DEFENSE Critical

Unauthenticated SQL Injection → Full Database Disclosure

Identified a time-based blind SQL injection in the URI path of a U.S. Government PKI endpoint with no authentication required, resulting in full database disclosure. Publicly disclosed on HackerOne.

Platform HackerOne Vector URI path Impact Full DB disclosure
View public report
FINDING · BUSINESS LOGIC Critical

Unauthorized Balance Top-Up via Business Logic Flaw

Discovered a business-logic vulnerability in an unvalidated API endpoint that allowed unauthorized account balance top-up — rated CVSS 9.8 by the program.

CVSS 9.8 Class Business logic Vector Unvalidated API
Read the write-up
FINDING · GRAPHQL API Critical

Blind SQL Injection in an Undocumented GraphQL Endpoint

Found and safely verified a P1 time-based blind SQL injection in an undocumented GraphQL endpoint, enumerating dozens of backend tables on a PostgreSQL/Greenplum database.

Priority P1 Backend PostgreSQL/Greenplum Vector GraphQL
Read the write-up
FINDING · ORACLE ORDS/APEX 24.2 High

Reflected XSS in Oracle ORDS/APEX

Responsibly disclosed a reflected cross-site scripting vulnerability directly to Oracle's security team, then built and published a Nuclei detection template for the wider community.

Disclosed Jun 2026 Vendor Oracle Status CVE pending

Additional confirmed findings — XSS, CSRF, SSRF, path traversal, IDOR and configuration disclosure — earned acknowledgement from Sony, BMW, American Airlines, ServiceNow and Hotmart. See Achievements.

Experience

Professional Experience

Client-facing security engineering, independent research, and community leadership.

Jul 2024 — Present

Security Engineer

Disclosify · disclosify.io · Dhaka, Bangladesh

  • Discovered and reported 500+ vulnerabilities across 40+ security projects and 50+ client organisations by performing manual web application and API penetration testing to OWASP and PTES methodology.
  • Sustained an 85–90% report acceptance rate, including 100+ high/critical and 250+ medium severity findings, by validating every issue with a working proof of concept before submission.
  • Identified authentication, authorization, broken access control and business-logic flaws — SSRF, IDOR, XSS, SQL injection, CSRF and OAuth — using Burp Suite Professional alongside targeted manual testing.
  • Delivered 200+ professional assessment reports with CVSS and CWE classification, business impact analysis and prioritised remediation guidance for technical and management audiences.
  • Closed findings end to end by coordinating daily with client engineering teams over Slack, agreeing severity, guiding remediation and verifying every fix through retest.
  • Expanded assessment coverage across large client attack surfaces by automating reconnaissance and attack-surface discovery in Python and Bash, and by chaining vulnerabilities to demonstrate real business impact.
500+ Vulnerabilities 40+ Engagements 85–90% Acceptance
Dec 2022 — Present

Independent Security Researcher

HackerOne & Bugcrowd · Remote

  • Achieved full database disclosure on a U.S. Department of Defense system by identifying an unauthenticated time-based blind SQL injection in the URI path of a U.S. Government PKI endpoint; publicly disclosed on HackerOne.
  • Ranked 42nd globally and 2nd in Bangladesh on the HackerOne VDP leaderboard (Apr–Jun 2025) by independently submitting 500+ platform reports against production enterprise applications and APIs, of which 140+ were triaged valid and rewarded.
  • Earned a CVSS 9.8 critical rating by discovering a business-logic flaw permitting unauthorized account balance top-up through an unvalidated API endpoint.
  • Enumerated dozens of backend database tables by discovering and safely verifying a P1 time-based blind SQL injection in an undocumented GraphQL endpoint on a PostgreSQL/Greenplum backend.
  • Earned acknowledgement from Sony, BMW, American Airlines, ServiceNow and Hotmart by reporting XSS, CSRF, SSRF, path traversal, IDOR and configuration disclosure through coordinated disclosure.
  • Scaled reconnaissance across large multi-domain attack surfaces by building custom Python and Bash tooling for subdomain enumeration, live-host probing and automated triage.
Rank #42 Global 1,242 Reputation 5 Vendor Acknowledgements
2024

Cyber Security Intern

CodeAlpha · Remote

  • Completed a structured offensive security internship by delivering vulnerability assessments, network scanning and web application tests with written findings and risk ratings.
2024 — 2025

Joint Secretary

DIU Cyber Security Club · Dhaka, Bangladesh

  • Kept a 4-person executive committee aligned across the academic year by coordinating club operations, event planning and internal communication.
2023 — 2024

Joint Lead Executive

DIU Cyber Security Club · Dhaka, Bangladesh

  • Grew practical security skills across the university community by planning and running technical workshops and internal CTF events.
2023 — 2024

One-to-One Mentor

DIU Cyber Security Club · Dhaka, Bangladesh

  • Moved students from theory to their first valid vulnerability reports by mentoring them one-to-one in web application security and bug bounty methodology.
2022 — 2023

Executive

DIU Computer Programming Club · Dhaka, Bangladesh

Skills

Core Competencies & Technical Skills

Methodology on the left, tooling on the right — the full stack I bring to an engagement.

Penetration Testing Web Application Penetration Testing Vulnerability Assessment API Security (REST & GraphQL) OWASP Top 10 OWASP API Security Top 10 Burp Suite Professional Broken Access Control Business Logic Vulnerabilities Authentication & Authorization Testing Vulnerability Triage Severity Assessment CVSS CWE Proof of Concept Development Remediation Verification Reconnaissance & OSINT Threat Modelling Risk Assessment Coordinated Vulnerability Disclosure Security Automation MITRE ATT&CK PTES NIST SP 800-115

Web & API Security

OWASP Top 10 & API Top 10XSSSQL InjectionSSRFRCELFICSRFIDORBOLA/BFLAGraphQLBusiness Logic

Tools

Burp Suite ProfessionalMetasploitNmapNessussqlmapNucleiffufBloodHoundNetExecImpacket

Recon & OSINT

subfinderamasshttpxnaabudnsxcrt.shShodanDomain AttributionASN Pivoting

Programming

PythonBashCJavaRustCustom Tooling & Burp ExtensionsLinux Server Administration

Frameworks

MITRE ATT&CKOWASPPTESNIST SP 800-115CVSS v3.1CWEISO/IEC 27001:2022Threat Modelling
Credentials

Education & Certifications

Academic background, industry certifications, and standards training.

Education

2022 — 2025

B.Sc. in Computer Science and Engineering

Daffodil International University, Dhaka, Bangladesh

2018 — 2020

Higher Secondary Certificate (Science)

Nizam Uddin Azgar Ali Degree College, Bangladesh

Certifications

eWPTX v3
Web Application Penetration Tester eXtreme · INE
CASA
Certified API Security Analyst · APIsec University
2026
ASCP
APIsec Certified Practitioner · APIsec University
APIsec Power User Plus
Hands-on API security exam · APIsec University
CNSP
Certified Network Security Practitioner · The SecOps Group
CAP
Certified AppSec Practitioner · The SecOps Group
ISO/IEC 27001:2022 Lead Auditor
Information security management systems
In progress
Achievements

Achievements & Recognition

Leaderboard standing, vendor acknowledgements and competitive results.

#42 / #2 BD
HackerOne VDP Leaderboard (Apr–Jun 2025)
1,242
Reputation Points
5.41
Signal Score
17.17
Impact Score
3+
Years Experience
10+
CTF Events

Vendor Acknowledgements

Recognised by security teams at:

Sony BMW American Airlines ServiceNow Hotmart

Competitive & Training

  • TOP 10 HackerOne Present Bug Hunt 2024
  • 4TH Runner-up — Flag Hunt 2023
  • 5TH Runner-up — IUT Fest 2024
  • TOP 10 BUET CTF 2023
  • 2022–23 KnightCTF — participant
  • CREATOR Inter-University CTF — web track problem creator
  • ROLE Social Media Manager — Leetcon 2023

Training: TryHackMe Junior Penetration Tester path · PortSwigger Web Security Academy labs · ICONCS 2022 CTF volunteer.

Projects

Security Research & Projects

Tooling I've built to scale my own research — and one platform I've shipped for others to use.

Featured Project

MultiScan — Vulnerability Intelligence Platform

A self-serve SaaS platform for security teams and bug bounty hunters, unifying active scanning, deep reconnaissance and automated triage into one workflow. Scope Guard validates every target before a scan runs, and proof-of-concept verification keeps findings signal over noise.

ReactFlaskNucleiStripe
Visit MultiScan
15+Integrated tools
11Vulnerability classes
7Phase engine pipeline
24/7Scheduled monitoring

Nuclei Detection Templates

Public Nuclei templates for real-world findings, including detection logic for the Oracle ORDS/APEX 24.2 reflected XSS I disclosed to Oracle's security team.

NucleiYAMLVulnerability Detection

Reconnaissance Automation Server

Self-hosted pipeline that runs subdomain enumeration and vulnerability scanning in parallel across large target lists, driving a headless browser for JS-heavy targets and feeding results straight into my triage workflow.

PythonFlaskPlaywrightBash

XSS Automation Toolkit

Automated XSS detection and exploitation toolkit for identifying cross-site scripting vulnerabilities across bug bounty targets.

PythonXSS

Burp Suite Extension — Parameter & SQLi Automation

Custom Burp Suite extension for automated parameter discovery and SQL injection testing, built to speed up repetitive manual-testing steps.

Burp ExtensionSQLi
Writing & Speaking

Writing & Speaking

Write-ups from the field, and sessions delivered to the community.

Writing

Medium

How I Discovered a Critical Unauthorized Balance Top-Up Vulnerability

The methodology behind the CVSS 9.8 business-logic finding, from spotting the unvalidated endpoint to safely proving impact.

Read on Medium
Medium

How a Hidden GraphQL Endpoint Led Me to a Critical SQL Injection

Discovering and safely verifying a P1 blind SQL injection hiding behind an undocumented GraphQL schema.

Read on Medium

Speaking

2026 · DIU Cyber Security Club

API Security, IDOR & Broken Access Control

A four-hour, in-person technical session on API security, IDOR and access-control failures.

Event page
10 Dec 2024 · DIU Cyber Security Club

Practical Bug Hunting Session

Live, hands-on bug-hunting walkthrough for club members.

Event page
5 Dec 2024 · Cybersecurity Seminar

How to Become a Bug Hunter

Guest talk on breaking into bug bounty hunting.

Event page
Contact

Get In Touch

Available for remote-first security engineering roles, consulting engagements and coordinated disclosure. I usually reply within a day.

Location
Dhaka, Bangladesh — open to relocation